HomeSecurityQRLJacking attack | Can bypass any QR Login System

QRLJacking attack | Can bypass any QR Login System

An Egyptian security researcher, Mohamed Baset, has published details about a new type of attack that successfully bypasses SQRLs (Secure QR Logins, also known as Secure, Quick, Reliable Logins). It is called QRLJacking and is a social engineering attack that relies on phishing and other similar techniques to trick the victim into scanning the wrong QR code.

QRLJacking attack | Can bypass any QR Login System

The attack works as follows: By requesting a QR code for the service the victim is trying to connect to, the QR code is modified to send the confirmation message to the attacker's computer.

The scammer can modify these login details, add data belonging to their PC, transmit data from their phone to a default login server , and access the victim's account from their computer.

This attack requires both the attacker and the victim to be online at the same time and a degree of technical skill required to modify the QR codes displayed by the Web services that use them.

SQRLs have become very popular in recent years and are often used on websites like WhatsApp and other messaging apps.

In a Facebook post, Baset says he tested his attack on websites such as WhatsApp, WeChat, Line, Weibo, QQ Instant Messaging, QQ Mail, Alibaba and many others.

Baset describes QRLJacking as a basic session hijacking attack that steals your session at the login step and sends the data to the fraudster.

[su_carousel source=”media: 106307,106304,106305″ limit=”6″ target=”blank” width=”100″ height=”20″ items=”1″ title=”no” arrows=”no”]

The attack is difficult to pull off and because it requires both parties to be online at the same time, it is likely to become a tool in the arsenal of APTs instead of classic cybercriminals who will still favor the broader approach of random spam and phishing campaigns.

Baset's discovery casts a shadow of doubt over the invincibility of SQRL as a login system, a system that has already been touted as the perfect login method, the only way that "blends" single-sign-on (SSO) and two-factor authentication (2FA) into a set of simple processes.

Of course, if a user takes into account the URL of the page through which they are going to log in to their account, as a basic anti-phishing technique, QRLJacking can be mitigated like any other social engineering attack.

More details about QRLJacking can be found on GitHub (proof of concept code) and OWASP (technical details). Here are demonstration videos below:

[su_youtube url=”https://youtu.be/4QwyBXiZhG0″ width=”640″ height=”380″]https://www.youtube.com/watch?v=B7o0qA4L4So[/su_youtube]

[su_youtube url=”https://youtu.be/JCoPSdQvESc” width=”640″ height=”380″]https://www.youtube.com/watch?v=B7o0qA4L4So[/su_youtube]

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS